Draft Act for the Implementation of the EU AI Regulation (Gesetz zur Durchführung der KI‑Verordnung - KI‑MIG)
proposedpolicy · Effective Jan 1, 2025
DE regulates AI through Draft Act for the Implementation of the EU AI Regulation (Gesetz zur Durchführung der KI‑Verordnung - KI‑MIG).
Draft Act for the Implementation of the EU AI Regulation (Gesetz zur Durchführung der KI‑Verordnung - KI‑MIG) · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
Germany's overall approach to Artificial Intelligence (AI) regulation is deeply rooted in a commitment to human-centric, trustworthy AI, consistently aligning with and actively shaping the broader European Union (EU) regulatory landscape. The nation views AI as a transformative technology with immense potential for economic growth and societal benefit, but also acknowledges the critical need for robust ethical, legal, and social safeguards. This philosophy is evident in its foundational National AI Strategy, which has been periodically updated to reflect evolving technological advancements and societal challenges. Germany aims to be a leading hub for AI research and innovation, while simultaneously ensuring that AI systems are developed and deployed in a manner that respects fundamental rights, promotes democratic values, and fosters public trust.The regulatory maturity in Germany is characterized by a blend of forward-looking policy initiatives and a proactive stance towards implementing EU-level binding legislation. Rather than developing an entirely separate national regulatory framework for AI, Germany has strategically focused on complementing and operationalizing the EU AI Act through national implementing laws. This approach ensures a harmonized legal environment across the EU, while allowing Germany to tailor specific national enforcement and innovation promotion mechanisms. The country also employs a range of non-binding instruments, such as action plans, standardization roadmaps, and multi-stakeholder platforms, to guide responsible AI development, build competencies, and facilitate public discourse on AI's impact on work and society.
Regulatory approach
Germany's regulatory approach to AI is primarily characterized by its strong horizontal alignment with the forthcoming EU AI Act, which adopts a risk-based framework. This means that national legislation, such as the Draft Act for the Implementation of the EU AI Regulation (KI-MIG), is designed to designate competent authorities, establish market surveillance mechanisms, and define national enforcement procedures for the EU's binding rules. The KI-MIG specifically outlines the Bundesnetzagentur as the central market surveillance and notifying authority, with sectoral exceptions like BaFin for financial-sector high-risk AI, demonstrating a hybrid approach that leverages existing regulatory expertise while establishing new coordination structures.Beyond direct implementation of EU law, Germany employs a significant amount of soft law, including policies, strategies, and guidelines, to shape its AI ecosystem. Documents like the BMBF AI Action Plan 2023 and the National AI Strategy — Update 2020 provide strategic direction, funding priorities, and ethical principles, but do not impose legally binding obligations or sanctions. These instruments aim to promote innovation, strengthen research, build competencies, and foster public dialogue around AI. They often emphasize human-centred design, transparency, robustness, and data protection, guiding stakeholders towards responsible development without prescriptive legal mandates, leaving substantive legal obligations to formal legislation and EU instruments. Germany's AI governance and enforcement landscape is evolving, with key roles being defined by the implementation of the EU AI Act. The Draft Act for the Implementation of the EU AI Regulation (KI-MIG) designates the Bundesnetzagentur (BNetzA) as the central market surveillance authority and, unless otherwise specified, the default notifying authority for national implementation. It is also proposed to host the Koordinierungs- und Kompetenzzentrum (KoKIVO), a coordination and competence center aimed at supporting other authorities on horizontal legal and technical questions and fostering uniform interpretation of the AI Regulation. This central role for the BNetzA underscores Germany's commitment to a coordinated and efficient oversight mechanism for AI systems across various sectors.Several other federal ministries and agencies play crucial roles in the broader AI ecosystem. The Federal Ministry for Digital and Transport (BMDV), which oversees the "Federal Ministry for Digital and State Modernisation (BMDS)" mentioned in the KI-MIG draft, is central to digital policy and the implementation of the AI Regulation. The Federal Ministry of Education and Research (BMBF) leads initiatives like the BMBF AI Action Plan and supports the Plattform Lernende Systeme, focusing on research, innovation, and skills development. The Federal Ministry of Justice (BMJ) is responsible for legislative proposals concerning criminal law and civil remedies related to AI, such as the deepfakes proposal and the Eckpunkte for a Law against Digital Violence. The Federal Ministry for Economic Affairs and Climate Action (BMWK) steers the German AI Standardisation Roadmap and contributes to the National AI Strategy, focusing on economic and industrial aspects. Additionally, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) provides crucial oversight on data protection matters, ensuring AI development and deployment comply with GDPR and national privacy laws.
Enforcement & penalties
With the upcoming implementation of the EU AI Act, Germany will adopt a robust framework for penalties and enforcement, particularly for high-risk AI systems. The Draft Act for the Implementation of the EU AI Regulation (KI-MIG) establishes national procedural rules for administrative fine procedures (Bußgeldverfahren) and other enforcement mechanisms necessary to implement the sanctions and oversight model set out by the AI Regulation. While specific fine ranges will be detailed in the final legislation, the EU AI Act itself foresees substantial penalties for non-compliance, including fines up to 35 million Euros or 7% of a company’s worldwide annual turnover for severe infringements, making it one of the most stringent regulatory frameworks globally.Beyond the EU AI Act, Germany is also developing specific criminal and civil enforcement mechanisms for AI-related harms. The Federal Council's draft for criminal-law protection against Deepfakes proposes criminal sanctions, including imprisonment up to two years or fines for ordinary cases, and up to five years for aggravated cases involving public dissemination or intimate content. This initiative aims to provide direct criminal-law protection for personality rights against digitally falsified media. Furthermore, the BMJ Eckpunkte for a Law against Digital Violence outlines enhanced civil remedies, such as expanded disclosure rights against online providers and the possibility of judge-ordered temporary account suspensions, to enable victims to take action against perpetrators of online harms. These measures collectively aim to create a comprehensive enforcement landscape, combining administrative, criminal, and civil avenues to address the diverse risks posed by AI.
Data protection
Germany's data protection framework is primarily governed by the EU's General Data Protection Regulation (GDPR), which is directly applicable across all Member States, and is supplemented by the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG). The GDPR establishes a high standard for the processing of personal data, requiring principles such as lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. It grants individuals extensive rights, including access, rectification, erasure, and the right to object to processing, while imposing strict obligations on data controllers and processors, including data protection impact assessments for high-risk processing and mandatory data breach notifications.The Data Strategy of the Federal Government explicitly emphasizes adherence to the GDPR and German data protection law as the normative baseline for all personal data use. It aims to increase the availability and reusability of data for various sectors while ensuring that citizens' rights and democratic values are protected. The BMJ Eckpunkte for a Law against Digital Violence also touches upon data protection by proposing expanded private disclosure rights against hosting providers and messaging services, subject to judicial oversight and data-protection safeguards to balance victim protection with freedom of expression and anonymity. The Federal Commissioner for Data Protection and Freedom of Information (BfDI) acts as the independent supervisory authority, responsible for monitoring and enforcing data protection laws, including in the context of AI applications.
Sector-specific rules
While Germany's primary AI regulatory framework is horizontal through the EU AI Act, several national initiatives and policy documents address sector-specific considerations for AI. In the financial services sector, the Draft Act for the Implementation of the EU AI Regulation (KI-MIG) explicitly designates BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) as the market surveillance authority for high-risk AI systems directly linked to regulated financial activities. This ensures that the specific complexities and risks within the financial sector are addressed by an authority with specialized expertise.For other critical sectors, policy documents and standardization efforts provide guidance. The BMBF AI Action Plan 2023 and the National AI Strategy — Update 2020 highlight specific initiatives for AI in healthcare and education, aiming to leverage AI for societal benefit while ensuring ethical and safe deployment. The German AI Standardisation Roadmap (DIN/DKE) identifies tailored standardization needs across various domains, including industrial automation, mobility, medicine, energy/environment, and financial services. These roadmaps recommend technical specifications and conformity assessment activities to operationalize legal requirements for AI systems in these specific contexts, emphasizing safety, robustness, and data quality. Furthermore, the BMAS-funded KI-Studios project focuses on the impact of AI in the workplace, promoting participatory design and ensuring AI applications are compatible with decent work and occupational health and safety standards.
International alignment
Germany is a staunch advocate for a harmonized and human-centric approach to AI regulation at the international level, with a particular focus on strong alignment with the European Union. The most significant development in this regard is the upcoming implementation of the EU AI Act, which Germany is actively preparing for through its Draft Act for the Implementation of the EU AI Regulation (KI-MIG). This national bill is designed to operationalize the EU AI Act's provisions, designate competent authorities, and establish enforcement mechanisms, ensuring a consistent regulatory environment across the EU. Germany has been a key player in the development of the EU AI Act, advocating for a risk-based approach that fosters innovation while upholding fundamental rights.Beyond the EU, Germany actively participates in and contributes to international discussions and initiatives on AI governance. The National AI Strategy — Update 2020 and the BMBF AI Action Plan 2023 explicitly underscore the importance of deepening European and international cooperation. Germany adheres to principles developed by organizations such as the OECD, which promote responsible AI innovation in line with democratic values, human rights, and sustainability. The German AI Standardisation Roadmap also emphasizes promoting international alignment and active participation in European and international standardization bodies (e.g., CEN/CENELEC JTC 21 and ISO/IEC JTC1/SC 42) to ensure interoperability and global acceptance of trustworthy AI standards. This multi-layered engagement reflects Germany's commitment to shaping a global framework for AI that is both innovation-friendly and ethically sound.
What's next
The most significant future development in German AI regulation is the progression and adoption of the Draft Act for the Implementation of the EU AI Regulation (KI-MIG). Currently at the referentenentwurf (draft bill) stage, this legislation is critical for establishing the national legal and administrative architecture required to enforce the EU AI Act. Its passage through cabinet, Bundesrat, and Bundestag readings will finalize the designation of market surveillance authorities, coordination mechanisms, and national enforcement procedures, fundamentally shaping how AI is regulated in Germany. The phased application dates of the EU AI Regulation (per Article 113) mean that Germany must ensure its national structures are ready in line with this timetable, with key deadlines approaching in 2026.Further legislative developments include the progression of the Federal Council draft for criminal-law protection against Deepfakes and the BMJ's proposed law against digital violence. Both initiatives, currently in draft or key points stages, aim to address emerging AI-related harms by strengthening criminal sanctions against malicious deepfakes and enhancing civil remedies for victims of online abuse. These proposals are subject to stakeholder consultations and parliamentary debate, with potential amendments before final adoption. Additionally, Germany's commitment to its National AI Strategy and the BMBF AI Action Plan ensures ongoing policy updates, funding calls, and initiatives focused on research, infrastructure, skills, and responsible AI application, indicating a dynamic and evolving regulatory and policy landscape for AI in the coming years.
policy · Effective Jan 1, 2025
policy · Effective May 6, 2024
Sources:
act · Effective Jan 30, 2024
EU institutions
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2021
strategy · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
guideline · Effective Jan 1, 2018
policy · Effective n/a
policy · Effective n/a
central_coordinator
Central market surveillance and notifying authority for AI systems, host of KoKIVO.
enforcement
Market surveillance authority for high-risk AI systems in the financial sector.
central_coordinator
Lead ministry for digital policy, including implementation of the EU AI Regulation.
central_coordinator
Supports AI research, innovation, and skills development; funds key AI initiatives and platforms.
central_coordinator
Responsible for legislative proposals concerning criminal law and civil remedies related to AI.
central_coordinator
Steers national AI strategy, promotes standardization, and supports economic and industrial AI applications.
data_protection
Independent supervisory authority for data protection and freedom of information.
advisory
National standardization bodies for AI, developing technical standards and conformity assessment activities.
advisory
Implements the BMAS KI-Studios project, focusing on participatory AI design in workplaces.
advisory
Coordinates the Plattform Lernende Systeme, a national multi-stakeholder platform for AI.
May 9, 2026 · news
Digital Minister emphasizes firm EU stance on AI policy
Open source →May 6, 2026 · international_agreement
Germany agencies publish joint report on high-risk requirements for AI-based medical devices
Open source →Apr 16, 2026 · law_amended
Germany drafts bill to close gaps in digital violence law
Open source →Mar 19, 2026 · news
Federal Cartel Office approves Adobe's acquisition of Semrush
Open source →Feb 13, 2026 · international_agreement
Canada and Germany sign AI joint declaration and launch Sovereign Technology Alliance
Open source →Feb 10, 2026 · law_amended
Germany approves AI Market Surveillance and Innovation Promotion Act
Open source →Dec 7, 2025 · news
Canada and Germany deepen collaboration on advanced technologies
Open source →Oct 16, 2025 · news
Data Protection Supervisory Authorities of Federal and State Governments adopt guidance on data protection for generative AI systems using RAG methodology
Open source →Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →Sep 11, 2025 · law_amended
German government starts consultation on law to implement EU rules
Open source →Jul 23, 2025 · news
Federal Office for Information Security publishes white paper on bias in Artificial Intelligence
Open source →Jul 9, 2025 · news
Germany launches consultation on data protection-compliant handling of personal data in large language models
Open source →Jun 26, 2025 · news
German state DPAs issue formal notice regarding Deepseek
Open source →Jun 15, 2025 · news
German federal and state governments release guidance on recommended technical and organisational measures for the development and operation of AI
Open source →May 22, 2025 · news
Cologne Higher Regional Court rules that Meta’s use of public user data for AI training compliant with GDPR and DMA
Open source →May 19, 2025 · news
Germany releases guidance questionnaire on privacy and AI
Open source →Apr 13, 2025 · international_agreement
India and Germany to deepen cooperation in AI, quantum tech
Open source →Mar 26, 2025 · law_amended
German coalition disagrees on AI regulation, digital sovereignty
Open source →Feb 10, 2025 · news
Paris Charter on AI signed
Open source →Jan 30, 2025 · news
German data protection authorities to investigate DeepSeek
Open source →Jan 5, 2025 · news
BSI adopts white paper on AI explainability in adversarial contexts
Open source →Nov 14, 2024 · news
Germany data protection authorities create AI working group
Open source →Oct 3, 2024 · news
France and Germany publish recommendations for secure use of AI coding assistants
Open source →Sep 29, 2024 · news
Federal Cartel Office extends special abuse control regime to Microsoft
Open source →Sep 25, 2024 · guideline_issued
German government reveals supervisory regime plan
Open source →May 20, 2024 · international_agreement
World leaders sign up to Seoul Declaration and Statement of Intent toward International Cooperation on AI Safety Science
Open source →May 6, 2024 · guideline_issued
DSK publishes guidelines for implementing AI in compliance with the GDPR
Open source →Feb 16, 2024 · news
Tech giants come together to combat deceptive deepfakes ahead of 2024 elections
Open source →Jan 30, 2024 · law_amended
Germany will approve the EU AI Act
Open source →Nov 18, 2023 · law_amended
France, Germany, Italy push for 'mandatory self-regulation' for foundation models in EU's AI law
Open source →